<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk" -->

---
title: ShinyHunters hacks Clop leak site, threatens to extort...
description: The ShinyHunters extortion gang breached and defaced the Clop ransomware group&#x27;s dark web leak site, exploiting an alleged unauthenticated file upload...
canonical: https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang | daily.dev
og:description: The ShinyHunters extortion gang breached and defaced the Clop ransomware group&#x27;s dark web leak site, exploiting an alleged unauthenticated file upload...
og:url: https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk
og:image: https://api.daily.dev/og/posts/fHUmymgmk.png
og:image:alt: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

The ShinyHunters extortion gang breached and defaced the Clop ransomware group's dark web leak site, exploiting an alleged unauthenticated file upload vulnerability in Grav CMS. ShinyHunters claims to have stolen source code, Grav CMS plugins, system logs, and Clop's Tor onion service private keys, which if valid would let them impersonate Clop's site. The attackers say they plan to extort Clop, giving them 72 hours to respond, framing the hack as retaliation for threats made by a Clop member following disputes over the 2025 Oracle E-Business Suite data theft campaign.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang>

## Questions this post answers

### How did ShinyHunters breach Clop's ransomware leak site?

ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS to compromise Clop's Tor-based data leak site. Using this access, they uploaded a defacement message, later replacing the site entirely with ASCII art of Umbreon, their Pokémon-themed logo, and claim to have stolen source code, Grav CMS plugins, and server logs from /var/log.

_Track emerging CMS vulnerabilities like this one on daily.dev before attackers exploit them against you._

### Why are ShinyHunters and Clop feuding?

The conflict traces back to Clop's 2025 Oracle E-Business Suite data theft campaign, which exploited a zero-day flaw tracked as CVE-2025-61882. ShinyHunters claims Clop obtained an exploit that originally belonged to them without authorization, and that a Clop representative later made violent threats against ShinyHunters members during the dispute, prompting this retaliatory hack.

_Follow how ransomware group rivalries and exploit disputes unfold by staying current on daily.dev._

### What did ShinyHunters claim to steal from Clop's servers?

ShinyHunters claims it gained full server access and exfiltrated source code, Grav CMS plugins, system logs, and all files under /var/log, which could expose authentication records and visitor IP addresses. They also claim to have obtained the private keys for Clop's Tor onion service, which if genuine would let them host a site at Clop's existing onion address.

_Keep tabs on ransomware infrastructure compromises like this via daily.dev's security coverage._

## Similar posts on daily.dev

- [ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security](https://daily.dev/posts/shinyhunters-wage-broad-corporate-extortion-spree-krebs-on-security-w8mqeq1jg) · Krebs on Security · 1 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"ShinyHunters hacks Clop leak site, threatens to extort ransomware gang","url":"https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk"},"datePublished":"2026-09-19T13:51:06.675Z","dateModified":"2026-09-19T13:51:33.175Z","description":"The ShinyHunters extortion gang breached and defaced the Clop ransomware group's dark web leak site, exploiting an alleged unauthenticated file upload...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5a9fb0ad94abe5aa4cd51b910c71609b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5a9fb0ad94abe5aa4cd51b910c71609b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ransomware,data-breach","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"ShinyHunters hacks Clop leak site, threatens to extort ransomware gang"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang-fhumymgmk#faq","mainEntity":[{"@type":"Question","name":"How did ShinyHunters breach Clop's ransomware leak site?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS to compromise Clop's Tor-based data leak site. Using this access, they uploaded a defacement message, later replacing the site entirely with ASCII art of Umbreon, their Pokémon-themed logo, and claim to have stolen source code, Grav CMS plugins, and server logs from /var/log. Track emerging CMS vulnerabilities like this one on daily.dev before attackers exploit them against you."}},{"@type":"Question","name":"Why are ShinyHunters and Clop feuding?","acceptedAnswer":{"@type":"Answer","text":"The conflict traces back to Clop's 2025 Oracle E-Business Suite data theft campaign, which exploited a zero-day flaw tracked as CVE-2025-61882. ShinyHunters claims Clop obtained an exploit that originally belonged to them without authorization, and that a Clop representative later made violent threats against ShinyHunters members during the dispute, prompting this retaliatory hack. Follow how ransomware group rivalries and exploit disputes unfold by staying current on daily.dev."}},{"@type":"Question","name":"What did ShinyHunters claim to steal from Clop's servers?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters claims it gained full server access and exfiltrated source code, Grav CMS plugins, system logs, and all files under /var/log, which could expose authentication records and visitor IP addresses. They also claim to have obtained the private keys for Clop's Tor onion service, which if genuine would let them host a site at Clop's existing onion address. Keep tabs on ransomware infrastructure compromises like this via daily.dev's security coverage."}}]}
```

